Trust Centre

Trust built from clear controls and honest evidence.

Review how Entivel approaches product security, identity, governance, data responsibility, delivery and transparent assurance.

Entivel does not use unsupported certification claims. Assurance is defined against the actual deployment, data, operating roles and requirements of each engagement.

01

Identity and access

Access begins with the user, tenant, role and responsibility. Sensitive areas and actions are designed to remain outside users who do not require them.

  • Multi-factor authentication capability
  • Role and permission boundaries
  • Session and account controls
  • Sensitive-action protection
02

Tenant and data boundaries

Customer information is organised inside tenant context with deployment, provider and data responsibilities defined for the engagement.

  • Tenant isolation model
  • Entity and location scope
  • Secure file access
  • Customer-specific deployment decisions
03

Operational control and evidence

High-impact work is designed around explicit status, responsible roles, approvals and records that support later investigation.

  • Maker-checker approval patterns
  • Audit and change history
  • Evidence attachments
  • Governed reversal and exception paths
04

Secure engineering lifecycle

Architecture, implementation, review, validation and controlled delivery shape the software lifecycle rather than being treated as a final checklist.

  • Threat and trust-boundary thinking
  • Code and dependency review
  • Environment and secret discipline
  • Controlled release and rollback
05

AI and integration controls

External systems and AI workflows introduce their own trust boundaries. Entivel defines tool access, data contracts, review and failure handling for the actual use case.

  • API authentication and validation
  • Retry and reconciliation
  • AI knowledge and tool boundaries
  • Human review and intervention
06

Customer assurance and incidents

Controls and responsibilities are evaluated against the real implementation, data, users and deployment. Incident and escalation responsibilities are agreed rather than implied.

  • Requirement and evidence review
  • Data and provider responsibility
  • Access validation
  • Incident, recovery and communication path